Network Vulnerability Assessment via Dynamic Service Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for assessing network vulnerabilities in large enterprises with numerous computing devices spread across multiple IP address ranges or subnets are inefficient, as they struggle to keep track of devices, ensure regular port scanning, and effectively allocate resources for vulnerability assessments.
Innovation Solution
A computer-implemented method that determines addresses for target devices, assigns port scanning and vulnerability scanning tasks to associated services, and generates reports based on scanning results, employing a tiered scanning approach to optimize resource usage and identify anomalous results.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If systematic port scanning is performed on all computing devices using a static IP address list, then vulnerability assessment can be performed, but the system cannot scale when the enterprise has a large number of computing devices spread across multiple IP address ranges or subnets
Solution Approach 1:
The patent segments the vulnerability assessment system into multiple independent components: IP address range management, device discovery services, port scanning services, and vulnerability assessment services. Each component operates independently and can be scaled separately, allowing the system to handle large numbers of devices across multiple subnets without becoming unmanageably complex.
Solution Approach 2:
The patent transitions from a flat, static IP address list approach to a multi-dimensional dynamic system that includes IP address ranges, subnet information, device discovery mechanisms, and real-time device status tracking. This dimensional expansion enables the system to scale across multiple network segments while maintaining manageability through structured organization.
2Measurement precision
If comprehensive port scanning is performed on all computing devices, then all vulnerabilities can be identified, but resource consumption increases significantly
Solution Approach 1:
The patent implements partial action by performing port scanning only on devices that are currently active and within monitored IP address ranges, rather than scanning all devices in the enterprise. The system dynamically adjusts scanning scope based on device discovery results, reducing unnecessary resource consumption while maintaining comprehensive vulnerability assessment for relevant devices.
Solution Approach 2:
The patent performs preliminary device discovery and status verification before initiating port scanning. By first identifying active devices and their current IP addresses through discovery services, the system avoids wasting resources scanning inactive devices or devices outside the monitoring scope, thereby reducing overall resource consumption while maintaining detection accuracy for active devices.
3Reliability
If manual tracking of computing devices is performed, then device inventory can be maintained, but the system cannot keep track of devices being brought into service, removed from service, or assigned different IP addresses
Solution Approach 1:
The patent implements self-service through automated device discovery services that continuously monitor the network for active devices, automatically update IP address bindings, and notify the vulnerability assessment system of device status changes. This eliminates the need for manual tracking while maintaining high reliability in device inventory accuracy, as the system self-updates based on observed network activity.
Solution Approach 2:
The patent establishes feedback loops where device discovery services continuously report device status changes to the central management system, which then adjusts the vulnerability assessment scope accordingly. This automated feedback mechanism ensures the system always has current information about active devices, IP address assignments, and service status without requiring manual intervention, thereby maintaining reliability while reducing operational effort.
Data Source
AI summary
One embodiment of the present disclosure sets forth a technique for analyzing network vulnerabilities. The technique includes determining an address for each target device included in a plurality of target devices; for each target device, assigning a port scanning task to an associated port scanning service, the port scanning task being associated with the target device via the address of the target device; for each port scanning task, receiving a port scanning result from the port scanning service assigned to the port scanning task, the port scanning result including a list of open ports for the target device associated with the port scanning task; for each open port included in each port scanning result, assigning a vulnerability scanning task to an associated vulnerability service; receiving a vulnerability scanning result for each vulnerability scanning task; and generating a report based on the port scanning results or the vulnerability scanning results.


